CVE-2022-2462: WordPress Transposh <=1.0.8.1 - Information Disclosure

CVE-2022-2462: WordPress Transposh <=1.0.8.1 - Information Disclosure-渗透云记 - 专注于网络安全与技术分享
CVE-2022-2462: WordPress Transposh <=1.0.8.1 - Information Disclosure
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2022-2462: WordPress Transposh <=1.0.8.1 – Information Disclosure

漏洞描述

WordPress Transposh plugin through is susceptible to information disclosure via the AJAX action tp_history, which is intended to return data about who has translated a text given by the token parameter. However, the plugin also returns the user's login name as part of the user_login attribute. If an anonymous user submits the translation, the user's IP address is returned. An attacker can leak the WordPress username of translators and potentially execute other unauthorized operations.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享